routed site-to-site ipsec packets loss



  • I followed official's doc setup a site-tosite ipsec with VTI, 2 sites and 2 pc are all KVM VM run into a DELL R730xd server, but there's issue:

    ping remote node has slightly packets loss;
    1_1542078232490_ping.png
    0_1542079351748_mtr.png

    below are configs & status:
    2_1542077918380_ipsec-config.png
    1_1542077918379_ipsec-allow-all.png
    3_1542077918381_ipsec-status.png